changeset 71:1a985a58dea5 puppet-3.6

Be specific about port blocking on Repeat Offender to try to prevent accidental lock-out
author IBBoard <dev@ibboard.co.uk>
date Sun, 18 Oct 2015 19:39:46 +0100
parents c91296a71160
children 33682e5b34fc
files common/fail2ban/jail.local
diffstat 1 files changed, 1 insertions(+), 1 deletions(-) [+]
line wrap: on
line diff
--- a/common/fail2ban/jail.local	Sun Oct 18 18:57:46 2015 +0100
+++ b/common/fail2ban/jail.local	Sun Oct 18 19:39:46 2015 +0100
@@ -41,7 +41,7 @@
 enabled  = true
 maxretry = 2
 filter   = ibb-repeat-offender
-action   = firewall-ban[name=RepeatOffenders,chain=Fail2Ban,port="1:65535"]
+action   = firewall-ban[name=RepeatOffenders,chain=Fail2Ban,port="80,443,25,465"]
 logpath  = /var/log/fail2ban.log
 findtime = 2592000
 bantime  = 2592000